DATE:
AUTHOR:
The Drata Team
Drata

New Framework Support: AIUC-1

DATE:
AUTHOR: The Drata Team

Drata now natively supports AIUC-1, a voluntary assurance standard for AI agents that covers data and privacy, security, safety, reliability, accountability, and societal risk. It combines technical testing, certification support, and accredited audits, and can be paired with AI-specific insurance as part of AIUC’s broader trust model.

Organizations building, adopting, or selling AI agents still struggle to prove those systems are safe, secure, and reliable. As a result, procurement slows down and third-party AI evaluation often remains ad hoc. Broader governance frameworks such as ISO 42001, NIST AI RMF, and the EU AI Act help, but they do not on their own provide the technical testing and agent-specific assurance many enterprise buyers now expect.

What's New

  • Continuous compliance, not a one-time badge: Continuous monitoring helps keep AIUC-1 evidence current as AI systems evolve, not just at audit time.

  • Integrated AI risk management: Data leakage, prompt injection, hallucinations, and jailbreak risks can be tracked in Drata’s risk register and mapped directly to AIUC-1 domains.

  • Third-party AI assurance: TPRM and the TPRM Agent help teams assess third-party AI suppliers against AIUC-1 criteria.

  • AI-powered trust operations: Audit Hub, Trust Center, and AI Questionnaire Assistance help turn AIUC-1 compliance into a sales-cycle asset.

Powered by LaunchNotes